Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.